Description
Incorrect Authorization (CWE-863) in Elasticsearch can lead to unauthorized data stream modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user with sufficient privileges over a single resource could use the Modify Data Streams API to modify a data stream to which they were not otherwise authorized, potentially injecting data into it or affecting its ability to be searched normally. This issue does not allow an attacker to read the contents of a data stream they do not otherwise have access to.
Published: 2026-10-06
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized data modification
Action: Patch
AI Analysis

Impact

The vulnerability is an Incorrect Authorization flaw (CWE-863) that allows an authenticated user with privileges on one resource to misuse the Elasticsearch Modify Data Streams API and alter a data stream for which they lack proper authorization. By changing the stream configuration or injecting data, the attacker can impact the stream’s indexing and search behavior, but the flaw does not expose the actual contents of the stream.

Affected Systems

Elastic:Elasticsearch products are affected. The grant specifies that any user who can authenticate and has sufficient permissions on a single resource can exploit the flaw via the Modify Data Streams API. Version information specific to the affected releases is not provided in the current data set.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated and possess elevated privileges on at least one resource, which limits the vector but still presents a significant risk if organizational access controls are relaxed. The attacker can alter search behavior and data insertion paths without reading the stream data.

Generated by OpenCVE AI on October 6, 2026 at 20:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Elastic’s latest Elasticsearch security update.
  • Re-evaluate and restrict Data Stream ACLs to ensure that only authorized users have modify rights, following the principle of least privilege.
  • Configure centralized logging or monitor audit trails for exploitation attempts.

Generated by OpenCVE AI on October 6, 2026 at 20:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization (CWE-863) in Elasticsearch can lead to unauthorized data stream modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user with sufficient privileges over a single resource could use the Modify Data Streams API to modify a data stream to which they were not otherwise authorized, potentially injecting data into it or affecting its ability to be searched normally. This issue does not allow an attacker to read the contents of a data stream they do not otherwise have access to.
Title Incorrect Authorization in Elasticsearch Leading to Unauthorized Data Stream Modification
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-10-06T19:56:32.845Z

Reserved: 2026-09-29T02:06:02.426Z

Link: CVE-2026-102407

cve-icon Vulnrichment

Updated: 2026-10-06T19:56:28.031Z

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:12.647

Modified: 2026-10-06T20:17:12.647

Link: CVE-2026-102407

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:00:06Z

Weaknesses